The package is clearly licensed and its repository matches the package, with release notes documenting this version. Its only registry release was over 11 years ago, and recent repository activity is absent, leaving strong abandonment concerns.
32%
Total Score
50
69
75
This is the package's only release, published over 11 years ago, with no releases in the last 12 months; that is strong evidence of abandonment despite the package being established.
There were no commits or active maintainers in the last three months, consistent with the repository having seen no recent development and materially increasing abandonment risk.
The repository has only 2 stars and no forks, indicating limited adoption and external validation; popularity is supporting evidence rather than the main reason for the low score.
Composer is used for builds, but no security scanning tooling is present. For a small package this is a hygiene gap rather than a standalone severe risk.
The repository has no security policy, reducing transparency about vulnerability reporting and handling; this compounds the lack of recent maintenance evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.